What the action targets
- device-protected key material needed for local vault access;
- future ordinary unlocks of affected local vaults;
- the practical usefulness of ciphertext left on that installation.
What it does not target
- portable encrypted backups exported earlier;
- backup recovery phrases stored elsewhere;
- files exported from the vault;
- copies held by recipients or other apps;
- Android system snapshots or external provider copies;
- previously written physical flash cells.
Example: In this fictional example, Chen triggers panic wipe locally on an Android phone still in their possession. A portable encrypted backup on an external drive remains restorable with its own backup phrase. A photo exported to a messaging app also remains outside NullVault. The action invalidates the local vault path; it does not reach into unrelated systems.
Why flash storage complicates “secure delete”
Modern storage controllers remap and wear-level physical cells. An app usually cannot prove that overwriting one logical location overwrote every historical physical representation. Destroying essential cryptographic key material can make remaining ciphertext unusable without claiming physical sanitization.
Before enabling or using panic wipe
Understand the trigger, test your recovery plan without triggering the destructive action, verify any encrypted backup, and decide whether permanent local loss matches the threat. Do not use it as routine cleanup or as a substitute for supported device erase procedures.
Panic wipe is an Android-only capability. NullVault is available on iPhone, but its iOS listing does not advertise panic wipe; iOS instead includes a configurable duress vault. See the panic wipe feature for the exact product boundary.
Guide reviewed: 28 August 2026.